{"id":"CVE-2026-87840","published":"2026-09-20T07:16:50.860","lastModified":"2026-09-21T13:34:57.127","description":"The Tripzzy  WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy  WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/7a81fd1d-9df5-4521-9a32-31fc9fe77960/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}